Personal website for fun projects and learning
- TypeScript
- React + TanStack Start
- DB: Neon
- Hosted: Docker in Fly.io
- Other stuff as we figure it out
A pre-commit hook scans staged changes with gitleaks and blocks the commit if a secret is found. bun install wires it up (via core.hooksPath); install the binary once:
# macOS
brew install gitleaks
# Linux
go install github.com/gitleaks/gitleaks/v8@latest # or grab a release binaryThe hook fails if gitleaks isn't on PATH. Emergency bypass: git commit --no-verify.
Run the owner CLI against prod without a credential on disk:
DATABASE_URL="$(npx neon@latest connection-string --project-id cold-recipe-98352824 --branch production)" bun run sticky-notes